Stage the install
Use a spare project or worktree the first time. Do not install an unknown plugin on a production repository.
Capture your Claude Code config before and after (a quick git commit of dotfiles helps). Rollbacks should be boring.
Evaluate with a fixed script
Write three tasks you already know the answer to. Run the plugin’s recommended commands. Score accuracy, speed, and whether it asked for surprising permissions mid-flight.
If the plugin wants MCP servers, enable one at a time. Bundling five new MCP endpoints in a single afternoon guarantees you will not know which one leaked data.
Team rollout
Document the approved plugin list in-repo. Shadow IT Claude plugins are how secrets wander into third-party tools.
Revisit the list quarterly — or after any incident. Pair with the rating scorecard so removals are evidence-based, not political.